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. ROUTING AND RECORD SHEET 


SUBJECT: (Optional) 
Federal Information Processing Standards (FIPS) 


EXTENSION 


[| 


pate OFFICER'S COMMENTS (Number each comment to show from whom 


INITIALS to whom. Draw a line across column after each comment.) 
FORWARDED 


a 


This action requests your con- 
currence on a letter for the 
DCL's signature, requesting the 
+ Secretary of Conmerce delegate 
his authority to waive: Federal 
i Information Processing Standards 
(FIPS) to the DCI or the DCI's 
4. designee. FIPS are promulgated 
by law and executive order by 
— the National Bureau of Standards. 
5. There aré about 80 standards, 
pertaining to hardware, software 
——. and data. To waive a standard 
S [ to procure non-conforming disk 
equipment, for example, an 
agency head must obtain the 
ss Z approval of the Secretary of 


2D00, Headquarters 
4 March 198] 


TO: (Officer designation, room number, and 
building) 


Commerce. The FIPS waiver pro- 
cedures present us with definite 
security problems, since they 
involve sharing information about 
T our computing facilities with 
another agency. 


FIPS waiver procedures are an 
|immediate problem because, in the 
| near future, ODP will require a 


FIPS waiver to obtain the new IBM 
disk technology, which we view as 
critical to solving our computer 

center space problems. We believe 


os aaa | 
12. the waiver should be granted by 
~ 


a senior Agency manager. Commerce 
has ignored a previous letter 
from the former DDA requesting a 
waiver authority delegation. We 
14. hope this DCI request will get 

the required action. The 
attached memorandum provides more 


details. 


STAT 


FORM 610 “Estee 
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SLYORANDUM POR: Director of Central Intelligence 


VIA? Leputy Director for Administration 
Seneral Counsel 


Lirector of Logistics me 
Sirector of Security . 


PROl: druce T. Johnson iJ 
Cirector of Cate Preeersing 


SULLIEC?T: recerél Information Precessing Standards (FIPS) 
PEPERENCE : Letter frow the DLA, Fr. Pon kortman, te the 


assistant Secretary for Productivity, Technolod 
and Innovetion, Department of Commerce, 
hr. derdan J. Paruch, dtd. Ff Kovernber 19&¢ 


1. Action Feauested: Paragraph 6 is a@ recommencation 
that you sign the atteched letter to the Secretary of Commerce 
recueeting thet independent euthority to waive Federal 
infermation Processing Standards (FIPS) be celegated to you & 
vour deslioneec. 


€ 


~ 


é. Fackground: Feceral Informetion Processing Stancarcs 
(FIPS) are promulgated by the bepartment of Commerce under the 


Frovisions of Public Law &6=306 (the Brooks Act) and Part 6 of 
Title 15 Code of Federal Feaulatiens. These standerds are 
rrescribed for Federal agencies in the acquisition, developrent, 
anc use of automatic data processing (ADP) systeme and in the 
interchange of data between and among agencies and with the 
public. The use of such standards, which are adopted after 
review by Federal acencies, industry, and the public, is intencec 
te recuce Covernment costs and improve the effectiveness of ADP 
Services. we are supportive of a well-manaced Federal ADY 
standerdse pregrar. Newever, the unigue nature of intellicence, 
with its concomitant security concerns, causes us special 
problems with respect to the open precedures surrounding the FIPS 
preorar. 
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SCBJECT:; Federal Inferretion erecessing Standerds (FIPS) 


3. Each FIPS stangard ree associated with it @ waiver 
precedure, whereby, if adverse economic or operetionel] impact can 
be demonstrated, @n acency may utilize ecuirnent or software that 
does net conform to the stancard. <sAuthority te waive these 
standares resides, depending on the standard, with the Mepertment 
or Commerce or the acency heed. (Fven these standerdre where the 
waiver authority resides with the agency head still recuire 
“coordination im advance* with the Pepartment.) Heretofore, we 
have not made any formal waiver recuests. As the standards 
rrogram has become more active and increased in seore, we find 
thet full canfermance with existing standards is not, in our 
judament, in the Agency's interest. In the future, we will 
require occasional waivers and, therefore, we ere concernee® abovt 
the security implications of FIP: waiver procedures. These 
Lrocedures generally will recuire sengitive intermation on Agency 
ADP systems be sheared with the Lepartment of Commerce. *e have 
described ovr security concerns in more Cetail in the attached 
letter to the Secretary cf Commerce. 


4. Our concern with the PIPS waiver procedures is net 
bypethetical. For example, we have a near-ters problem with FIPS 
CO-63, which deal with input/cutput interface standards anc would 
deny us use of some new mess storace (disk drive) technolody 
vitel to our ADP programs. We believe we have a etrong case for 
# waiver from FIPE €0-€3. KRowever, the existing waiver 
peocedures for FIPS 6€-63 recuire approval of the waiver recuest 
by the Secretary of Cemmerce. se ere reluctant to make cur case 
through these existing precedures because of the precedent it 
sete and the security implicetione of havine enother cepartment 
in our ALCP procurerent process, Acain, our concern if with all 
PIPS anc not just FIPS 6C-€3, ~~ 

Se The Secretary cf Commerce, under the previous 
acdwinistration, delecatec certain FIPS authority to the forver 
Assistent Secretary for Productivity, Technology ané Innevation, 
Dr. Jorden J. Baruch. On 5 Sovember 1S€C, our former Reruty 
hirector for Administration, Don kertman, sent a letter te 
Dy. Beruch requesting « ceneral delegation of FIBS waiver 
authority te the DCI. ‘ihe letter (reference) outlined cur 
eecurity rationale for recuestine such a delegation. Three 
months have elapsed anc we have had no teormel response. The 
informal response is that Commerce is taking action te deleuate 
weiver authority, perteining specifically ta FIPS 6¢=63, te the | 


2 
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SUPGECY: Federal Information Processing Utandarcs (FESS 


heace of all asencies. we vwelccwe this wove, but unfortunetely 
it will not be tirely enough for cur immeciste procurement 
neees, Steh a eeleaation will require a minimum of three anc 
more realistically six wonthse to implement and even then it will 
address only FIPE 66-63, net other current er future FIPS. A 
timely response from the Eecretary of Comuerce te the attoched 
waiver Geleqation recuest would cverceme these crawbeacke. 


€. Fecommendation: We recemmend thet you send the attached 
letter to the Secretary of Commerce reiterating our previcus 
unanswered request for a delegation of independent authority to 
you or your degiqnee to arant waivers to FeCeral Information 
Processing Standards (FIPS). 


Attechwents: 
Letter to the Secretary cf Commerce 
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SUEGECT: Pederal information Processing Standarc.s (FIPS) 


CONCUR : 


a 


/3{_ “Mat 


ee et ntl nts ate mamma 


/s/ Daniel B. Silver 


Gereral Counsel a Ge, i ac 


fs/ Jarces Hy id vOsnald 
¥irector of Loaistics — 


i] 


mn ne ee mite tees tt A NAAN tt i mi 


Fjrectcr cf Security pe en Sn Fey 


Is/ Wiiliicin J. Catey 


Sirector cf Central Inteilicence 


cpeses/Eomijalf —_ brebruary1941) 


Distribution: 

Crianinal - C1, v/fatts. 

- ELCI, w/fatte. 

- Leecutive fenistry, w/fatts. 


cae a pr nan oe nm mat 


Generel Counsel, w/fatts. 
~ Director of Logirtics, w/atts. 
~ Uirector of Security, w/fatts. 


at feet Some Seed fend Renae 
{ 


2 = D/COnP 
2 = UDB/HS 
2 = CvUP Reaisery 


MAR 4 ‘1981 


ane einen ns amt tncgeer en pontine agg 


bate 


IR xt 


5 MAR 1321 


ee ering stneette itininstnne  Ay oeenA: Aee enn 


~ Deputy Lirector for Administration, w/atts. 
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Laecutive Registry 


She HMonoreble Maleolm Baldridge 
The om y of Commerce 

LACE stitution Avenue 
Washington, DP. f. 20270 


In a letter to Oe. Jordan Beruch, former Assistant Secretary | 
for Productivity, Technology and Innovation, Bepartment of 


Commerce, dated 4 Movember 1980, this Ageney's former Deputy 


Directo > for Administration, Vy. Don Wortman, requested that the 
Department delegate to the Director us aap oaiaas Intelligeneco (FT) 
independent authority eS eee ant, for this Agency, waivers of the 
provisi ms of Pederal nforie tion See Standards (FIPS) 


promuigated by the Department. ‘Fhe ietter set forth various 
seeurity coneerns whieh are raised oy the current FIPS watver 
procedures and explained the delegation of procurement eine ty 
whieh, on aeeount of simiiar eoneerns, the Agency has obtaines 

from the Generai Serviees Administration. We have reecived no 

formal response to this request ne reeause of the importance I 

attach to it; To weula oe to take this cpportunity to reiterate 
our concerns and the s1 ota ae procedure that 1 beliave 
will alleviate thers. 


pad 
feu 
a 


or jert 


As you know, requests for waivers from VIPS, cepenn ing on 
andard, either require coordination in advance with he 
ment, or your epproval. In order to support a waiver 
ast, extensive documentation ts typie aly SG WF 
Department. For example, one group of FIPS (HIPS §0-63) 
explieitly deserine whet must be inelu ded in a weiver reguest: 
u a deseription of the existing or planned ADP system for 
whieh the waiver is being requested, 2) a description of the 
system configuration, identifying those items for whieh the 


eo 
ef 


waiver is being requested, and ineluding a description of plannoc 
expansion of the system eonfiguration at any time duping 3 ite Tif 
eyele, and 3) a jus ification for the waiver, inclucing a 
deseripticn and diseussion of the major adverse ccenomie oF 
operational impact that would result through eonfoermanec to this 


standard ag eomparer to the alternative for whieh the waiver is 
requested ; " 
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this waiver reavent procedure is cause for considerable 
security concern to senier CiA managerent. Under the atatuteory 
provisions ci the Hational Security Act oft 1547, as amended, the 
Cl is charged with the responsibility for protecting 
intelligence sources and methods. Relatine this to current enc 
anticipated acquisitions ot auteratic data processing ecuipment 
(ADPE), it is opr consigered judorent that Cisclosure thrduch 
the waiver process of the Acency's capabilities and lecation cf 
its resources would rot cnly edversely affect the PLSpEr 
Aiescharce of this responsibility bur would aleg, in sere Casec, 
represent @ craéve threat to national security. Our ADPE, whetoer 
eeneral purpose or unicue te our recuirements, is utilized fer 
extremely sensitive intelligence information precessing, 
communications, and reel-time intelligence-operation 
recuirements. The type and location cf eauipment represent, for 
fFereien intelligence avencies, prime tergets in terme of 
operational utilizaticn, ecvirment capabilities, or the 
readability of siqnal emaraticns., Cf ecual significance is the 
fact that, in certain instances, identification with the Agency 
ef specitic equipment or siter of operations could he extremely 
erharrassing to the Unitec States or to friendly foreign 
qevernvents. 


lt is my firm opinion that 6 celegation of independent IPO 
waiver euthority to the Director of Central Intellicence vith 
apprepriate redelesation autherity would ceet protect the 
national security interests Involved in the acauisition anc use 
of ®Orr by the Central Intelligence Agency for intelligence 
information processine, communications and intelligence 
eperaticonel appliecaticns. i therefore recuest that the Secretary 
of Comperce Celeqate to the MCI incerendent authority to orant,. 
for this Agency, waivers of the provisions of Federal Information 
Processing Standards promulaateé by the Perartment of Commerce. | 


Your favorable consi¢eration of this recvest will be 
sincerely appreciate’. I would be rleased tc make available the 
arprepriate members of my staff to Gevelop in conjunction with 
your representatives a suitable deleqation of waiver euthority. 
My Director of Data Processing, Fr. Sruce Te. Jonnsen, is 


aveileble to answer any technical cvertions you may have. He can 


YOUNGS, 


sf William J. Casey 
yi ? | LORS of sb! FPailliaw J. Casey 


E’ 
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